Description
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=2050228
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-076.txt
https://www.syss.de/pentest-blog/fehlerhafte-autorisierung-bei-red-hat-single-sign-on-750ga-syss-2021-076
Related Vulnerabilities
CVE-2016-10563 Vulnerability in npm package go-ipfs-dep
CVE-2017-16026 Vulnerability in maven package org.webjars:request
CVE-2022-36901 Vulnerability in maven package org.jenkins-ci.plugins:http_request
CVE-2023-49486 Vulnerability in maven package com.jfinal:jfinal
CVE-2022-31129 Vulnerability in maven package org.webjars.bower:momentjs